Skip to main content

The HIPAA Business Associate Agreement (BAA), Explained for 2026

By Joseph Abear ·
HIPAA BAA

Last updated: August 13, 2026

A Business Associate Agreement (BAA) is the contract that makes a vendor legally responsible for the patient data it handles for you. No BAA, no patient data: that is the rule before any technology question. The HIPAA business associate agreement is also the most misunderstood document in healthcare IT. Practices think signing one makes them compliant. It does not. Vendors think a security page can replace one. It cannot. This guide covers what the law requires the contract to say. It covers who must sign one and who refuses. And it shows how to get one signed without a sales maze. Everything cites the rule itself, so you can check each claim.

TL;DR: Quick answer

  • A vendor that creates, receives, maintains, or transmits protected health information (PHI) for you is a business associate (45 CFR § 160.103). You need a signed BAA before it touches PHI (45 CFR § 164.308(b)).

  • The contract's required contents are set by law (45 CFR § 164.504(e)): permitted uses, safeguards, breach reporting, subcontractor flow-down, patient access duties, termination, and return or destruction of PHI.

  • A signed HIPAA business associate agreement does not make anyone compliant by itself. It assigns legal duty. The safeguards still have to exist.

  • Operating without one is a violation on its own, no breach required. The 2026 penalty tiers run from $145 to $2,190,294 per violation.

  • Web hosts, email providers, schedulers, and form tools all sit inside this rule. Many mainstream vendors refuse to sign. That refusal is your answer.

What is a business associate agreement?

HIPAA BAA Who Needs One

Start with the entities. HIPAA covers two groups. Covered entities are providers, health plans, and clearinghouses. A business associate is any outside company that handles PHI for a covered entity. The web host storing intake forms. The email service carrying patient messages. The billing platform. The IT contractor with server access. The BAA is the written contract between the two. It binds the vendor to HIPAA's rules. It also gives the government a direct line of enforcement against that vendor. Since the 2013 Omnibus Rule, business associates carry direct liability of their own. The HIPAA business associate agreement is what puts that chain in writing.

Who needs one, and how far down the chain it goes

The test is function, not job title. Does the vendor create, receive, maintain, or transmit PHI on your behalf? Then a HIPAA business associate agreement is required before the data flows (45 CFR § 164.308(b)). The chain does not stop at one hop. Your vendor's vendors need one too. A subcontractor that touches PHI signs with the business associate above it, on the same terms. Two groups sit outside the rule. Vendors that never touch PHI need nothing. And pure carriers, like an internet service provider that only moves encrypted traffic, can fall under the narrow conduit exception. A web host does not qualify for that exception, because a host stores your data. Whether your own site is in scope is covered in who needs HIPAA-compliant hosting.

What the law requires the contract to say

HIPAA BAA Seven Provisions

The required contents are not up for negotiation. They are listed in 45 CFR § 164.504(e). A real HIPAA business associate agreement must contain each of these.

Required provision

What it means in practice

Permitted uses and disclosures

The vendor may only use PHI for the contracted work, never in ways HIPAA forbids

Safeguards

The vendor must apply the Security Rule's safeguards to electronic PHI

Reporting

The vendor must report improper uses and breaches of unsecured PHI to you

Subcontractor flow-down

Anyone the vendor hires who touches PHI must accept the same restrictions

Patient rights support

The vendor must support access, amendment, and accounting duties (§§ 164.524, 164.526, 164.528)

Termination

You may terminate if the vendor materially violates the contract

Return or destruction

At the end, the vendor returns or destroys all PHI and keeps no copies

HHS publishes sample provisions you can compare against any vendor's paper. When a vendor hands you a HIPAA business associate agreement, check it against this table. A contract missing the subcontractor flow-down or the return-of-data clause is not a compliant BAA, whatever its title says.

What a BAA does not do

HIPAA BAA What It Doesnt Do

The contract assigns duty. It does not perform the work. A signed BAA over an unencrypted server with shared logins is a lawsuit with a signature on it. Compliance still requires the safeguards: encryption, access controls, audit logs, backups, and a written risk analysis (45 CFR § 164.308(a)(1)(ii)(A)). This is the same both-halves rule we apply in every review: the contract half and the configuration half. One without the other fails. The five tests we use to score any vendor, BAA scope first, are in our ranking of the best HIPAA compliant hosting providers.

No BAA is a violation all by itself

HIPAA BAA Violation By Itself

This is the point practices learn during an audit instead of before one. Operating without a required BAA violates 45 CFR § 164.308(b) on contract grounds alone. No breach needs to happen. OCR asks for BAAs early in nearly every investigation. A missing one is one of the fastest findings it can make. Under the penalty amounts effective January 28, 2026, violations run from $145 to $2,190,294 each. The exposure sits quietly in ordinary tools. The practice website on a host with no BAA. The scheduler whose terms prohibit PHI. The personal inbox receiving intake forms. Every vendor in the patient-data path needs its own agreement. A missing one anywhere breaks the chain.

Who signs, and who refuses

HIPAA BAA Who Signs Who Refuses

The market splits cleanly. Specialist healthcare vendors sign as a matter of course. The big productivity suites sign on paid business plans: Google Workspace in the Admin Console, Microsoft 365 inside its Product Terms. The big clouds sign: AWS through Artifact, with Azure and Google Cloud on the same model. And a long list of mainstream tools refuse or restrict. Most consumer website hosts sign nothing. Some vendors cover only one product, the way GoDaddy signs only for its Microsoft 365 email, not its hosting. A refusal is useful information. It tells you exactly where patient data cannot go, whatever the vendor's security page claims. Our vendor verdict library tests these one company at a time, always starting with the HIPAA business associate agreement question.

How to get a BAA signed without the runaround

HIPAA BAA Without the runaround

Here is the pain nobody warns you about. At many vendors, the HIPAA business associate agreement lives behind an enterprise sales process. A request form. An account review. A wait. Sometimes a plan upgrade. Meanwhile your project stalls. The data cannot flow until the signature exists. Three ways to shorten it. First, prefer vendors that include the BAA by default instead of gatekeeping it. Second, send the § 164.504(e) table above with your request, so the scope discussion happens once. Third, get the signed copy into your compliance records before launch, not after. We built our own process around that pain: the BAA is included at every tier of our HIPAA compliant hosting, from the $79 per month self-managed server up. On managed plans from $229 per month, we sign it within 24 hours, with migration included. We sell this, so weigh it as a disclosure. If your worry is the vendors you already have, our client-side compliance review maps your whole vendor chain and shows which links have no agreement behind them. Ask us anything about the BAA chain and you will get a direct answer.

Frequently asked questions

Is a business associate agreement legally required?

Yes, whenever a vendor handles PHI for a covered entity or another business associate. The requirement sits at 45 CFR § 164.308(b) and § 164.502(e). Operating without one is itself a violation, separate from any breach.

Can I use a BAA template?

HHS publishes sample provisions, and many vendors offer standard agreements built on them. A template is a fine starting point when it contains every § 164.504(e) element. Have counsel confirm the scope matches the actual service, because the gaps live in the specifics.

Does a signed BAA make me HIPAA compliant?

No. The HIPAA business associate agreement assigns legal responsibility. Compliance still requires the safeguards, the policies, and a written risk analysis on both sides of the contract. The BAA is the first test, not the whole exam.

Who provides the BAA, the vendor or the practice?

Either side can supply the paper. In practice, large vendors use their own standard agreement and will not negotiate it. Specialist vendors sign quickly on either version. What matters is that every § 164.504(e) provision is present and the signed copy is in your records.

Do subcontractors need their own BAA?

Yes. A subcontractor that creates, receives, maintains, or transmits PHI signs a BAA with the business associate above it. The restrictions flow down the whole chain, and a missing link anywhere is a violation.

What should I do if a vendor refuses to sign?

Believe them, and keep PHI out of that tool. A refusal usually reflects the vendor's own terms of service. Move the patient-data function to a vendor that signs, or isolate the refusing tool so it never touches PHI.

Recap: HIPAA business associate agreement

To recap, the HIPAA business associate agreement is the contract that makes a vendor legally responsible for your patient data. The law sets its required contents at § 164.504(e): permitted uses, safeguards, breach reporting, subcontractor flow-down, patient rights support, termination, and return of data. Every PHI-touching vendor needs one, down the whole chain. It never substitutes for the safeguards, and its absence is a violation on its own. Check every vendor against the table, keep the signed copies, and treat a refusal as the honest answer it is.

This article is general information, not legal advice. Regulatory citations reflect 45 CFR Parts 160 and 164 as of August 2026; the 2026 penalty tiers reflect the amounts effective January 28, 2026. Confirm your obligations with qualified counsel and base your safeguards on a written risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed August 2026.

Sources